UK GDPR · Aim Automations Ltd · weaim.io
Version 1.2 · Revised 21 August 2026
This Data Processing Agreement governs the processing of personal data and special category data by Aim Automations Ltd on behalf of its customers, in accordance with Article 28 of the UK GDPR and the Data Protection Act 2018.
What changed in version 1.2.Breach notification to the Customer shortened from 72 hours to 24 hours, so the Customer retains time to meet its own regulatory deadline. Added: assistance with data protection impact assessments and prior consultation; the duty to flag an infringing instruction; express liability for sub-processors; a defined consequence where the Customer objects to a sub-processor; return or deletion at the Customer’s choice; a concrete audit right; and a record of processing. Section 4 sub-processor list updated.
For the purposes of the UK GDPR and the Data Protection Act 2018, the Customer acts as the Data Controller and Aim Automations Ltd acts as the Data Processor.
This Agreement applies to all personal data and special category data, including health and care records, processed by Aim on behalf of the Customer in the course of providing the Aim platform and related services.
This Agreement forms part of, and is subject to, the customer agreement between the Parties. Where the customer agreement contains a data protection obligation that is more protective of the Customer than this Agreement, that obligation prevails.
Provision of digital care management and business software, including care planning, medication records (eMAR), scheduling, rostering, finance, reporting, communication, recruitment, marketing and AI-assisted drafting features.
For the term of the customer agreement, plus the post-termination period set out in section 10.
Aim processes personal data only on the Customer’s documented instructions, including instructions given through use of the platform and through support requests, unless required to do otherwise by law, in which case Aim will inform the Customer of that requirement before processing unless the law prohibits it.
Aim will inform the Customer promptly if, in Aim’s opinion, an instruction from the Customer infringes the UK GDPR, the Data Protection Act 2018 or any other applicable data protection provision. Aim may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
Aim ensures that all personnel authorised to process personal data are subject to appropriate obligations of confidentiality, whether contractual or statutory, and that those obligations survive the end of their engagement.
Aim implements appropriate technical and organisational measures under Article 32, including:
Aim does not sell, rent or commercially exploit Customer data, and does not use it for any purpose other than providing and supporting the services, complying with law, and protecting the security and integrity of the platform.
Taking into account the nature of the processing, Aim assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights, including access, rectification, erasure, restriction, portability and objection.
Taking into account the nature of the processing and the information available to Aim, Aim assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, including:
Aim maintains a written record of all categories of processing carried out on behalf of the Customer, as required by Article 30(2), and makes it available to the Customer on request.
The Customer gives Aim general written authorisation to engage sub-processors, subject to this section 4. The sub-processors engaged at the date of this Agreement are:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Vercel | Application hosting, edge content delivery and DNS | United Kingdom, with limited processing outside under transfer safeguards |
| Neon | Managed database infrastructure | United Kingdom |
| OpenAI | AI text processing via API only | United States, under transfer safeguards |
| Anthropic | AI text processing via API only | United States, under transfer safeguards |
| SendGrid (Twilio) | Transactional email delivery | United States, under transfer safeguards |
| Firebase (Google) | Real-time in-app messaging | United Kingdom, with limited processing outside under transfer safeguards |
| Stripe | Payment processing | United Kingdom and European Economic Area |
| Amazon Web Services | Application and data hosting | United Kingdom (London, eu-west-2) |
The current list is maintained by Aim and available at any time on request to care@weaim.io.
Aim imposes on each sub-processor, by written contract, data protection obligations that are equivalent to those in this Agreement and that are sufficient to meet the requirements of Article 28.
Aim remains fully liable to the Customer for the performance of each sub-processor’s data protection obligations. Where a sub-processor fails to fulfil those obligations, Aim remains liable to the Customer for that failure as if it were Aim’s own.
Aim will give the Customer at least 30 days’ written notice before adding or replacing a sub-processor. Where the Customer objects in writing within that period on reasonable data protection grounds:
Aim’s AI sub-processors are engaged on enterprise API terms, not consumer terms. Where the provider offers it and the processing is eligible, Aim configures zero data retention so that Customer data is not retained by the provider after the request is served. Where a specific feature is not eligible for zero data retention, Aim will identify it to the Customer on request and confirm the retention period that applies at the provider. Aim holds a signed business associate agreement with its AI sub-processors where the provider offers one.
Aim hosts production systems and Customer care data within the United Kingdom.
Aim does not transfer Customer care data outside the United Kingdom or the European Economic Area except where an appropriate transfer mechanism is in place.
Certain sub-processors identified in section 4.1 process limited personal data outside the United Kingdom. Each such transfer is covered by the provider’s data processing terms incorporating the UK International Data Transfer Agreement, or the Standard Contractual Clauses together with the UK Addendum, and by a transfer risk assessment carried out by Aim. Copies of the relevant safeguards are available to the Customer on request.
Aim maintains documented incident response procedures to identify, investigate, contain and remediate security incidents, and tests them periodically.
Aim notifies the Customer without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting the Customer’s data. This period is deliberately shorter than the Customer’s own 72 hour deadline for notifying the Information Commissioner’s Office under Article 33, so that the Customer retains sufficient time to assess and report.
So far as the information is available to Aim at the time, the notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a point of contact. Where the full information is not available at the time, Aim provides it in phases without further undue delay.
Aim provides reasonable assistance to support the Customer’s regulatory obligations, including any notification the Customer must make to the Information Commissioner’s Office or to affected data subjects, and does not require the Customer to bear Aim’s costs of investigating a breach caused by Aim.
Aim makes available to the Customer all information necessary to demonstrate compliance with Article 28 and with this Agreement, including its security overview, its NHS Data Security and Protection Toolkit submission, its record of processing under section 3.8, and its current sub-processor list.
The Customer, or an auditor mandated by the Customer, may audit Aim’s compliance with this Agreement once in any twelve month period, and additionally following any personal data breach affecting the Customer’s data. Audits are subject to reasonable written notice of at least 30 days, are conducted during normal business hours, must not disrupt service availability or the confidentiality of Aim’s other customers, and are subject to confidentiality undertakings.
Nothing in this section limits any audit or inspection right of the Information Commissioner’s Office or any other competent supervisory authority.
AI features are provided only via enterprise application programming interfaces operated by Aim’s AI sub-processors. Customer data is never entered into consumer AI tools.
Customer data is not used to train, fine-tune or evaluate any AI model, whether Aim’s or a sub-processor’s. Data is transmitted on the minimum necessary principle, limited to what the requested feature requires.
Where the provider offers it and the processing is eligible, zero data retention is configured so that no Customer data persists at the provider after the request is served. Where a feature is not eligible, Aim identifies it and the applicable provider retention period to the Customer on request, in accordance with section 4.5.
AI-generated outputs are stored only within Aim’s United Kingdom hosted systems and are encrypted at rest.
AI-assisted drafting and task execution operate under the Customer’s control. Outputs affecting care documentation are produced as proposals requiring human review and approval before publication, and the Customer remains responsible for every decision to accept, amend or reject an output.
The Customer is responsible for:
On termination or expiry of the customer agreement, and at the Customer’s written election, Aim will either return the Customer’s personal data to the Customer or delete it. This choice is the Customer’s, in accordance with Article 28(3)(g).
Aim retains the Customer’s data for 6 months from the effective date of termination so that the Customer may export it. Where the Customer makes no election within that period, Aim permanently deletes the data at the end of it.
On deletion, data is permanently removed from production systems and residual copies are removed from backups through normal rotation. Aim confirms deletion in writing on request.
Exports are provided in structured, commonly used, machine-readable formats, and Aim provides a complete export within 20 business days of written request, at no charge for a single export.
Where Aim is required by law to retain any personal data beyond the period in section 10.2, it will inform the Customer, retain only what the law requires, and continue to protect it under this Agreement until deletion is permitted.
Aim will not withhold the Customer’s data as leverage in a commercial dispute. Where a dispute exists, Aim will provide the export against payment of undisputed amounts only.
Each Party remains responsible for its own compliance with data protection law. Nothing in this Agreement limits liability where such limitation is not permitted by law, including liability to a data subject under Article 82. Any limitation of liability in the customer agreement applies to claims under this Agreement, save where the law does not permit it.
This Agreement is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.
Data protection and security queries: care@weaim.io
This annex records where each requirement of Article 28 of the UK GDPR is met, so that a controller or auditor can verify compliance without reading the whole document.
| Article 28 requirement | Where met |
|---|---|
| 28(3)(a) Process only on documented instructions, including on transfers | 3.1, 5.2, 5.3 |
| 28(3) Final paragraph: inform controller of an infringing instruction | 3.2 |
| 28(3)(b) Confidentiality commitments from authorised personnel | 3.3 |
| 28(3)(c) Article 32 security measures | 3.4 |
| 28(2) and 28(4) Sub-processor authorisation, flow-down and liability | 4.1, 4.2, 4.3, 4.4 |
| 28(3)(e) Assist with data subject rights | 3.6 |
| 28(3)(f) Assist with Articles 32 to 36, including DPIAs and prior consultation | 3.7, 6.4 |
| 28(3)(g) Delete or return at the controller’s choice | 10.1, 10.2 |
| 28(3)(h) Make information available and allow audits and inspections | 7.1, 7.2, 7.3 |
| Article 30(2) Processor record of processing | 3.8 |
| Article 33(2) Notify the controller of a breach without undue delay | 6.2, 6.3 |
| Area | Measure |
|---|---|
| Encryption at rest | AES-256 across production databases and object storage |
| Encryption in transit | TLS 1.2 or higher for all connections |
| Access control | Role-based, least privilege, enforced at tenancy boundary so that no customer can access another customer’s environment |
| Authentication | Multi-factor authentication supported for all user accounts |
| Production access | Restricted to named personnel, logged, and reviewed periodically |
| Audit logging | Access to personal data is logged and retained for investigation |
| Backups | Encrypted, with documented restoration procedures and defined rotation |
| Segregation | Multi-tenant architecture with logical separation between customer environments |
| Incident response | Documented procedures for identification, investigation, containment, remediation and notification |
| Personnel | Confidentiality obligations, and data protection training for personnel with access to personal data |
| Assurance | NHS Data Security and Protection Toolkit submission maintained at Standards Met; ICO registration maintained |
| Review | These measures are reviewed at least annually and updated where necessary |
Version history.Version 1.0, initial issue. Version 1.1, revised 25 June 2026. Version 1.2, revised 21 August 2026: breach notification to the Customer shortened to 24 hours; added assistance with data protection impact assessments and prior consultation; added the duty to flag an infringing instruction; added express liability for sub-processors; added a defined consequence where the Customer objects to a sub-processor; added return or deletion at the Customer’s choice; added a concrete audit right and a record of processing; expanded the technical and organisational measures; added the Article 28 compliance map.
Aim Automations Ltd, company number 16579415, registered in England and Wales. care@weaim.io · weaim.io